PT-2021-2557 · Apple+8 · Safari+15
Francisco Alonso
·
Published
2021-02-01
·
Updated
2024-06-15
·
CVE-2021-1788
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Apple Safari versions prior to 14.0.3
macOS Big Sur versions prior to 11.2
Security Update versions prior to 2021-001 Catalina
Security Update versions prior to 2021-001 Mojave
tvOS versions prior to 14.4
watchOS versions prior to 7.3
iOS versions prior to 14.4
iPadOS versions prior to 14.4
Description:
A use after free issue was addressed with improved memory management. Processing maliciously crafted web content may lead to arbitrary code execution. The issue is related to the WebKitGTK module, which is used for displaying web pages in Apple Safari and various Apple operating systems, including Mac OS, iOS, iPadOS, watchOS, and tvOS.
Recommendations:
For macOS Big Sur, update to version 11.2 or later.
For Security Update Catalina, apply Security Update 2021-001 or later.
For Security Update Mojave, apply Security Update 2021-001 or later.
For tvOS, update to version 14.4 or later.
For watchOS, update to version 7.3 or later.
For iOS, update to version 14.4 or later.
For iPadOS, update to version 14.4 or later.
For Safari, update to version 14.0.3 or later.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Safari
Security Update
Suse
Ubuntu
Ios
Ipados
Macos Big Sur
Tvos
Watchos